Web Technician Online

Mixed content: find insecure resources on an HTTPS page

Open Developer Tools, reload the affected page and read the Console warnings.

What does this mean?

Mixed content occurs when an HTTPS page requests resources over HTTP. Scripts, frames or other active content may be blocked; images may be upgraded or fail. A valid certificate for the page therefore does not guarantee that every element is loaded securely.

What should I check first?

Open Developer Tools, reload the affected page and read the Console warnings. Copy the insecure resource URL and identify whether it is an image, script, stylesheet, frame or API request. Test important pages, including forms and checkout, because a single homepage test may miss template-specific resources.

How can I diagnose the cause?

Find where the URL is stored: a theme template, CMS content, plugin setting, stylesheet or external integration. Confirm that the resource itself is actually available over HTTPS before replacing the scheme. Redirects on your own domain cannot repair an external service that only supports HTTP.

How do I fix it safely?

Update the specific source to its supported HTTPS URL or remove an obsolete integration. For WordPress database replacements, use a tool that understands serialized data and test on staging after a file and database backup. Do not perform an unrestricted text replacement across the database with a basic editor.

Verify the fix and know when to contact your provider

Clear only relevant caches and retest for warnings and missing functionality. A Content Security Policy can provide additional protection, but it should not conceal a broken dependency. Ask the resource provider for a secure endpoint if none exists; ask your host for help if secure assets unexpectedly redirect back to HTTP.

Work through these checks in order

  1. Reload with the Console open and copy the first mixed-content resource URL. Open its HTTPS equivalent in a separate tab to confirm that a secure resource actually exists.
  2. Find the exact reference in its template, page content or plugin settings. Edit the source of the URL rather than adding a second, competing redirect layer.
  3. Reload after clearing the relevant page cache, then test the feature that used the resource. Absence of a warning alone is insufficient if the browser simply blocked a script and left a form broken.

Which tool can help?

URL encoder / decoder

DNS tools show one resolver’s public answers. Record explainers do not authenticate a message, and calculators do not monitor a server. Use the evidence alongside your provider’s logs.

Reference

Official technical documentation